CVE-2026-87848: Unknown Mpcx Lightbox

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthenticated visitors to retrieve the title, content or excerpt of arbitrary posts, including private, draft, pending, trashed and password-protected ones.

Affected products

  • Unknown Mpcx Lightbox: from 1.2.2, up to and including 1.2.5

Published 2026-09-23. Last modified 2026-09-23.